Description
Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change.
Users are recommended to upgrade to version 3.2.1, which fixes this issue.
Users are recommended to upgrade to version 3.2.1, which fixes this issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vjqc-g788-f378 | Session Fixation Apache DolphinScheduler |
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 18 Mar 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache dolphinscheduler |
|
| CPEs | cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache dolphinscheduler |
Thu, 29 Aug 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-384 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-29T15:08:36.166Z
Reserved: 2023-12-06T02:25:09.094Z
Link: CVE-2023-50270
Updated: 2024-08-02T22:16:46.169Z
Status : Analyzed
Published: 2024-02-20T10:15:08.140
Modified: 2025-03-18T17:38:29.743
Link: CVE-2023-50270
No data.
OpenCVE Enrichment
No data.
Github GHSA